Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For supply chain security, you might be interested in cargo-vet[0], a tool for coordinating and requiring manual reviews of open source dependencies. Both Mozilla and Google[1] have started publishing their audits.toml files, which are machine-readable files describing what source code reviews they have performed.

[0] https://github.com/mozilla/cargo-vet

[1] https://opensource.googleblog.com/2023/05/open-sourcing-our-...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: